GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa30c58e199fb31b4fb8520d3eaae1465cd5834a719
GraphQL introspection enabled at /graphql Types: 185 (by kind: ENUM: 19, INPUT_OBJECT: 83, OBJECT: 77, SCALAR: 6) Operations: - Query: Query | fields: publicAutocomplete, publicInterview, publicInterviews, publicPlayerInterview, publicSearchCollections - Mutation: Mutation | fields: createInterview, createInterviewSegments, createLanguageInstance, saveInterview, softDeleteInterview Directives: deprecated, include, skip, specifiedBy (total: 4)
Open service 20.105.232.38:443 · newapi.istorima.org
2026-01-23 10:29
HTTP/1.1 404 Not Found
Content-Length: 63
Connection: close
Content-Type: application/json; charset=utf-8
Date: Fri, 23 Jan 2026 10:30:14 GMT
Strict-Transport-Security: max-age=15552000; includeSubDomains
Content-Security-Policy: default-src 'self';style-src 'self' 'unsafe-inline' cdn.jsdelivr.net fonts.googleapis.com;font-src 'self' fonts.gstatic.com;img-src 'self' data: cdn.jsdelivr.net;script-src 'self' https: 'unsafe-inline' cdn.jsdelivr.net
X-DNS-Prefetch-Control: off
Expect-CT: max-age=0
X-Frame-Options: SAMEORIGIN
X-Download-Options: noopen
X-Content-Type-Options: nosniff
X-Permitted-Cross-Domain-Policies: none
Referrer-Policy: no-referrer
X-XSS-Protection: 0
{"statusCode":404,"message":"Cannot GET /","error":"Not Found"}
Open service 20.105.232.38:443 · newapi.istorima.org
2026-01-09 20:09
HTTP/1.1 404 Not Found
Content-Length: 63
Connection: close
Content-Type: application/json; charset=utf-8
Date: Fri, 09 Jan 2026 20:10:03 GMT
Strict-Transport-Security: max-age=15552000; includeSubDomains
Content-Security-Policy: default-src 'self';style-src 'self' 'unsafe-inline' cdn.jsdelivr.net fonts.googleapis.com;font-src 'self' fonts.gstatic.com;img-src 'self' data: cdn.jsdelivr.net;script-src 'self' https: 'unsafe-inline' cdn.jsdelivr.net
X-DNS-Prefetch-Control: off
Expect-CT: max-age=0
X-Frame-Options: SAMEORIGIN
X-Download-Options: noopen
X-Content-Type-Options: nosniff
X-Permitted-Cross-Domain-Policies: none
Referrer-Policy: no-referrer
X-XSS-Protection: 0
{"statusCode":404,"message":"Cannot GET /","error":"Not Found"}
Open service 20.105.232.38:443 · newapi.istorima.org
2026-01-02 18:09
HTTP/1.1 404 Not Found
Content-Length: 63
Connection: close
Content-Type: application/json; charset=utf-8
Date: Fri, 02 Jan 2026 18:09:37 GMT
Strict-Transport-Security: max-age=15552000; includeSubDomains
Content-Security-Policy: default-src 'self';style-src 'self' 'unsafe-inline' cdn.jsdelivr.net fonts.googleapis.com;font-src 'self' fonts.gstatic.com;img-src 'self' data: cdn.jsdelivr.net;script-src 'self' https: 'unsafe-inline' cdn.jsdelivr.net
X-DNS-Prefetch-Control: off
Expect-CT: max-age=0
X-Frame-Options: SAMEORIGIN
X-Download-Options: noopen
X-Content-Type-Options: nosniff
X-Permitted-Cross-Domain-Policies: none
Referrer-Policy: no-referrer
X-XSS-Protection: 0
{"statusCode":404,"message":"Cannot GET /","error":"Not Found"}
Open service 20.105.232.38:443 · newapi.istorima.org
2025-12-22 20:26
HTTP/1.1 404 Not Found
Content-Length: 63
Connection: close
Content-Type: application/json; charset=utf-8
Date: Mon, 22 Dec 2025 20:26:46 GMT
Strict-Transport-Security: max-age=15552000; includeSubDomains
Content-Security-Policy: default-src 'self';style-src 'self' 'unsafe-inline' cdn.jsdelivr.net fonts.googleapis.com;font-src 'self' fonts.gstatic.com;img-src 'self' data: cdn.jsdelivr.net;script-src 'self' https: 'unsafe-inline' cdn.jsdelivr.net
X-DNS-Prefetch-Control: off
Expect-CT: max-age=0
X-Frame-Options: SAMEORIGIN
X-Download-Options: noopen
X-Content-Type-Options: nosniff
X-Permitted-Cross-Domain-Policies: none
Referrer-Policy: no-referrer
X-XSS-Protection: 0
{"statusCode":404,"message":"Cannot GET /","error":"Not Found"}